CVE-2024-53295

Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

07 Feb 2025, 20:29

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - Vendor Advisory
CWE NVD-CWE-Other
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
First Time Dell data Domain Operating System
Dell
Summary
  • (es) Las versiones de Dell PowerProtect DD anteriores a 8.3.0.0, 7.10.1.50 y 7.13.1.20 contienen una vulnerabilidad de control de acceso inadecuado. Un usuario malintencionado local con privilegios bajos podría aprovechar esta vulnerabilidad y provocar una escalada de privilegios.

01 Feb 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-01 05:15

Updated : 2025-02-07 20:29


NVD link : CVE-2024-53295

Mitre link : CVE-2024-53295

CVE.ORG link : CVE-2024-53295


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-1220

Insufficient Granularity of Access Control

NVD-CWE-Other